The Rapid7 Blog:
Your Signal in the Security Noise

Insights, stories, and guidance from our global security and research teams.

Weekly security updates — no spam. Privacy Policy.

Rapid7 Analysis: CVE-2022-1388

Threat Research

Rapid7 Analysis: CVE-2022-1388

Rapid7 Labs's avatar

Rapid7 Labs

Patch Tuesday - May 2022

Detection and Response

Patch Tuesday - May 2022

Greg Wiseman's avatar

Greg Wiseman

What's Changed for Cybersecurity in Banking and Finance: New Study

Exposure Management

What's Changed for Cybersecurity in Banking and Finance: New Study

Jesse Mack's avatar

Jesse Mack

Active Exploitation of F5 BIG-IP iControl REST CVE-2022-1388

Exposure Management

Active Exploitation of F5 BIG-IP iControl REST CVE-2022-1388

Ron Bowes's avatar

Ron Bowes

[Infographic] Cloud Misconfigurations: Don't Become a Breach Statistic

Threat Research

[Infographic] Cloud Misconfigurations: Don't Become a Breach Statistic

Rapid7's avatar

Rapid7

Metasploit Wrap-Up: May 6, 2022

Exposure Management

Metasploit Wrap-Up: May 6, 2022

Alan David Foster's avatar

Alan David Foster

Rapid7’s first comic: XDR vs. Exploito

Detection and Response

Rapid7’s first comic: XDR vs. Exploito

Amy Hunt's avatar

Amy Hunt

Rapid7 Analysis: CVE-2022-29799 "Nimbuspwn"

Threat Research

Rapid7 Analysis: CVE-2022-29799 "Nimbuspwn"

Rapid7 Labs's avatar

Rapid7 Labs

XSS in JSON: Old-School Attacks for Modern Applications

Cloud and Devops Security

XSS in JSON: Old-School Attacks for Modern Applications

Julius Callahan's avatar

Julius Callahan

Is Your Kubernetes Cluster Ready for Version 1.24?

Cloud and Devops Security

Is Your Kubernetes Cluster Ready for Version 1.24?

Alon Berger's avatar

Alon Berger

MDR, MEDR, SOCaaS: Which Is Right for You?

Security Operations

MDR, MEDR, SOCaaS: Which Is Right for You?

Aaron Wells's avatar

Aaron Wells

Rapid7 Analysis: CVE-2022-22954

Threat Research

Rapid7 Analysis: CVE-2022-22954

Rapid7 Labs's avatar

Rapid7 Labs

Cloud-Native Application Protection (CNAPP): What's Behind the Hype?

Products and Tools

Cloud-Native Application Protection (CNAPP): What's Behind the Hype?

Jesse Mack's avatar

Jesse Mack

Metasploit Wrap-Up: 4/29/22

Products and Tools

Metasploit Wrap-Up: 4/29/22

Shelby Pace's avatar

Shelby Pace

Widespread Exploitation of VMware Workspace ONE Access CVE-2022-22954

Exposure Management

Widespread Exploitation of VMware Workspace ONE Access CVE-2022-22954

Caitlin Condon's avatar

Caitlin Condon

Rapid7 Analysis: CVE-2022-0543

Threat Research

Rapid7 Analysis: CVE-2022-0543

Rapid7 Labs's avatar

Rapid7 Labs

How to Strategically Scale Vendor Management and Supply Chain Security

Detection and Response

How to Strategically Scale Vendor Management and Supply Chain Security

AJ Debole's avatar

AJ Debole

Velociraptor Version 0.6.4: Dead Disk Forensics and Better Path Handling Let You Dig Deeper

Detection and Response

Velociraptor Version 0.6.4: Dead Disk Forensics and Better Path Handling Let You Dig Deeper

Carlos Canto's avatar

Carlos Canto

Rapid7 Analysis: CVE-2022-29464

Threat Research

Rapid7 Analysis: CVE-2022-29464

Rapid7 Labs's avatar

Rapid7 Labs

Opportunistic Exploitation of WSO2 CVE-2022-29464

Exposure Management

Opportunistic Exploitation of WSO2 CVE-2022-29464

Jake Baines's avatar

Jake Baines

Metasploit Weekly Wrap-Up: 4/22/22

Exposure Management

Metasploit Weekly Wrap-Up: 4/22/22

Dean Welch's avatar

Dean Welch